This software package is currently in pre-release state. That means changes can occur frequently and only the latest released version will be supported with security and bug fixes. It is therefore not recommended to use this package in productive environments.
If you discover a vulnerability, please contact the author team directly via email. Pull-requests with proposed solutions are explicitly welcomed as well.